Virus Trouble

Hi

First, reboot to normal mode

Then use otmoveit to this -> C:\DOCUME~1\User\x.exe

Run combofix and post its log along with a fresh HijackThis log (taken in normal mode)
 
here is combofix log:

"User" - 07-04-01 17:02:49 Service Pack 2
ComboFix 07-03-27.4.2 - Running from: "C:\Documents and Settings\User\Desktop"


(((((((((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))


"C:\WINDOWS\system32\awtqnkh.dll"


* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *



((((((((((((((((((((((((((((((( Files Created from 2007-03-01 to 2007-04-01 ))))))))))))))))))))))))))))))))))


2007-04-01 17:10 602,112 --a------ C:\DOCUME~1\User\x.exe
2007-04-01 17:01 759,003 ---hs---- C:\WINDOWS\system32\ehhjl.bak1
2007-04-01 17:01 48,708 --a------ C:\WINDOWS\system32\kyrlaiiu.dll
2007-04-01 17:00 280,676 ---hs---- C:\WINDOWS\system32\ljhhe.dll
2007-04-01 16:50 26,694 --a------ C:\WINDOWS\system32\pmnnmlj.dll
2007-04-01 12:19 <DIR> d----c--- C:\avenger
2007-03-31 19:23 <DIR> d----c--- C:\!KillBox
2007-03-30 18:16 2,874 --a------ C:\WINDOWS\system32\tmp.reg
2007-03-30 18:15 79,360 --a------ C:\WINDOWS\system32\swxcacls.exe
2007-03-30 18:15 53,248 --a------ C:\WINDOWS\system32\Process.exe
2007-03-30 18:15 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2007-03-30 18:15 40,960 --a------ C:\WINDOWS\system32\swsc.exe
2007-03-30 18:15 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2007-03-30 18:15 135,168 --a------ C:\WINDOWS\system32\swreg.exe
2007-03-30 16:54 524,288 --ah----- C:\DOCUME~1\ADMINI~1\NTUSER.DAT
2007-03-26 20:04 <DIR> d-------- C:\VundoFix Backups
2007-03-22 17:19 <DIR> d-a------ C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
2007-03-03 16:39 <DIR> d-------- C:\WINDOWS\system32\Dell
2007-03-03 16:39 <DIR> d-------- C:\Program Files\Dell
2007-03-03 16:32 <DIR> d-------- C:\Program Files\Motherboard Monitor 5
2007-03-03 14:15 <DIR> d-------- C:\DOCUME~1\User\APPLIC~1\Screenshot Sender


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2007-04-01 17:11 26694 --a------ C:\WINDOWS\system32\mljghhi.dll
2007-03-26 18:51 -------- d-------- C:\Program Files\windows live toolbar
2007-03-26 18:49 -------- d-------- C:\Program Files\yahoo!
2007-03-26 18:48 -------- d-------- C:\Program Files\msn messenger
2007-03-22 19:21 -------- d-------- C:\Program Files\norton internet security
2007-03-03 16:33 -------- d-------- C:\Program Files\java
2007-02-06 17:40 -------- d-------- C:\Program Files\windows media connect 2
2007-01-24 18:47 48776 --a------ C:\WINDOWS\system32\s32evnt1.dll
2007-01-19 13:53 51056 --a------ C:\WINDOWS\system32\sirenacm.dll
2007-01-08 20:01 17408 --a------ C:\WINDOWS\system32\corpol.dll


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries & legit default entries are not shown

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\ctfmon.exe"
"MsnMsgr"="\"C:\\Program Files\\MSN Messenger\\MsnMsgr.Exe\" /background"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"ATIPTA"="\"C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe\""
"igfxtray"="C:\\WINDOWS\\System32\\igfxtray.exe"
"igfxhkcmd"="C:\\WINDOWS\\System32\\hkcmd.exe"
"igfxpers"="C:\\WINDOWS\\System32\\igfxpers.exe"
"Dell Photo AIO Printer 922"="\"C:\\Program Files\\Dell Photo AIO Printer 922\\dlbtbmgr.exe\""
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_11\\bin\\jusched.exe\""
"ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
"osCheck"="\"C:\\Program Files\\Norton Internet Security\\osCheck.exe\""
"Symantec PIF AlertEng"="\"C:\\Program Files\\Common Files\\Symantec Shared\\PIF\\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\\PIFSvc.exe\" /a /m \"C:\\Program Files\\Common Files\\Symantec Shared\\PIF\\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\\AlertEng.dll\""

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"


[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{7D064D71-DD76-4596-90C0-921766AD560A}"=""

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\awtqnkh
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ljhhe
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pmnnmlj

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0

*newlycreated* - HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\LEGACY_COMHOST


Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\Norton Internet Security - Run Full System Scan - User.job


********************************************************************

catchme 0.2 W2K/XP/Vista - userland rootkit detector by Gmer, 17 October 2006
http://www.gmer.net

scanning hidden processes ...

scanning hidden services ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0

********************************************************************

Completion time: 07-04-01 17:13:55
C:\ComboFix2.txt ... 07-04-01 12:33
C:\ComboFix3.txt ... 07-04-01 11:54
 
Logfile of HijackThis v1.99.1
Scan saved at 17:19:13, on 01/04/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\igfxpers.exe
C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe
C:\WINDOWS\System32\igfxsrvc.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Dell Photo AIO Printer 922\dlbtbmon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\User\Desktop\HJT.exe

O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: (no name) - {7D064D71-DD76-4596-90C0-921766AD560A} - C:\WINDOWS\system32\pmnnmlj.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {E0649FE9-87D8-49D5-A1A3-1CB32D2EBE8D} - C:\WINDOWS\system32\ljhhe.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\System32\igfxpers.exe
O4 - HKLM\..\Run: [Dell Photo AIO Printer 922] "C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-GB/a-UNO1/GAME_UNO1.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: awtqnkh - awtqnkh.dll (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: ljhhe - C:\WINDOWS\system32\ljhhe.dll
O20 - Winlogon Notify: pmnnmlj - C:\WINDOWS\SYSTEM32\pmnnmlj.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: dlbt_device - Dell - C:\WINDOWS\system32\dlbtcoms.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing)
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe

i can see another few more infected files, can't it be stopped from mutating?
 
Hi

Well, we definitely need more research, there's something we don't know, otherwise vundo would have been gone long time ago:

Create a Startup List
  • Open HiJackThis
  • Click on the "Config..." button on the bottom right
  • Click on the tab "Misc Tools"
  • Check off the 2 boxes next to the Box that says "Generate StartupList log"
  • Copy and past the StartupList from the notepad into your next post

Download F-Secure Blacklight and save it to your desktop -> https://europe.f-secure.com/blacklight/try.shtml

Doubleclick blbeta.exe, accept the agreement, click Scan, then click Next

You'll see a list what have been found. A log will appear to your desktop, it is named fsbl.xxxxxxx.log (xxxxxxx will be random numbers).

DON'T choose Rename if something was found!

Post the contents of fsbl.xxxx.log to here (xxxx= random numbers,blacklight log from your desktop)

Post:

- startuplist
- blacklight log
 
Due to the lack of feedback this Topic is closed.

If you need this topic reopened, please request this by sending the moderating team
a PM with the address of the thread. This applies only to the original topic starter.

Everyone else please begin a New Topic.
 
i'm in the middle of a norton antivirus scan which i did whilst i knew i had vundo and it didnt find anything, but its now just come up with 13 viruses including another trojan: metajuan. here is the startuplist thing: StartupList report, 10/04/2007, 18:59:38
StartupList version: 1.52.2
Started from : C:\Documents and Settings\User\Desktop\HJT.EXE
Detected: Windows XP SP2 (WinNT 5.01.2600)
Detected: Internet Explorer v7.00 (7.00.6000.16414)
* Using default options
==================================================

Running processes:

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\User\Desktop\HJT.exe

--------------------------------------------------

Checking Windows NT UserInit:

[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

ATIPTA = "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
igfxtray = C:\WINDOWS\System32\igfxtray.exe
igfxhkcmd = C:\WINDOWS\System32\hkcmd.exe
igfxpers = C:\WINDOWS\System32\igfxpers.exe
Dell Photo AIO Printer 922 = "C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe"
SunJavaUpdateSched = "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
ccApp = "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
osCheck = "C:\Program Files\Norton Internet Security\osCheck.exe"
Symantec PIF AlertEng = "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run

CTFMON.EXE = C:\WINDOWS\system32\ctfmon.exe
MsnMsgr = "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background

--------------------------------------------------

Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:

Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*

Shell & screensaver key from Registry:

Shell=Explorer.exe
SCRNSAVE.EXE=*Registry value not found*
drivers=*Registry value not found*

Policies Shell key:

HKCU\..\Policies: Shell=*Registry value not found*
HKLM\..\Policies: Shell=*Registry value not found*

--------------------------------------------------


Enumerating Browser Helper Objects:

(no name) - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll - {1E8A6170-7264-4D0F-BEAE-D42A53123C75}
(no name) - C:\WINDOWS\system32\ljhhe.dll - {2487839D-CBCF-4CCF-9826-6390CFACAFAE}
(no name) - C:\WINDOWS\system32\wtdwiqmp.dll - {57E218E6-5A80-4f0c-AB25-83598F25D7E9}
(no name) - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}
(no name) - C:\WINDOWS\system32\pmnnmlj.dll - {7D064D71-DD76-4596-90C0-921766AD560A}
(no name) - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll - {9030D464-4C02-4ABF-8ECC-5164760863C6}

--------------------------------------------------

Enumerating Task Scheduler jobs:

Norton Internet Security - Run Full System Scan - User.job

--------------------------------------------------

Enumerating Download Program Files:

[SysProWmi Class]
InProcServer32 = C:\WINDOWS\system32\Dell\SystemProfiler\SysPro.ocx
CODEBASE = http://support.dell.com/systemprofiler/SysPro.CAB

[Shockwave ActiveX Control]
InProcServer32 = C:\WINDOWS\system32\macromed\Director\SwDir.dll
CODEBASE = http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab

[UnoCtrl Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\GAME_UNO1.dll
CODEBASE = http://messenger.zone.msn.com/EN-GB/a-UNO1/GAME_UNO1.cab

[MessengerStatsClient Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\messengerstatsclient.dll
CODEBASE = http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab

[Crucial cpcScan]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\cpcScan.dll
CODEBASE = http://www.crucial.com/controls/cpcScanner.cab

[MessengerStatsClient Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\MessengerStatsPAClient.dll
CODEBASE = http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab

[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\System32\Macromed\Flash\Flash9b.ocx
CODEBASE = http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

--------------------------------------------------

Enumerating ShellServiceObjectDelayLoad items:

PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
CDBurn: C:\WINDOWS\system32\SHELL32.dll
WebCheck: C:\WINDOWS\system32\webcheck.dll
SysTray: C:\WINDOWS\System32\stobject.dll
WPDShServiceObj: C:\WINDOWS\system32\WPDShServiceObj.dll

--------------------------------------------------
End of report, 5,725 bytes
Report generated in 0.020 seconds

Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only
 
here is fsbl log, it said nothing was found:

04/10/07 20:31:16 [Info]: BlackLight Engine 1.0.61 initialized
04/10/07 20:31:16 [Info]: OS: 5.1 build 2600 (Service Pack 2)
04/10/07 20:31:21 [Note]: 7019 4
04/10/07 20:31:21 [Note]: 7005 0
04/10/07 20:31:29 [Note]: 7006 0
04/10/07 20:31:30 [Note]: 7011 1124
04/10/07 20:31:30 [Note]: 7026 0
04/10/07 20:31:30 [Note]: 7026 0
04/10/07 20:31:34 [Note]: FSRAW library version 1.7.1021
04/10/07 20:56:51 [Note]: 2000 1012
04/10/07 20:57:04 [Note]: 7007 0
 
Hi

Juan = almost same as vundo

Run another scan with combofix and post its log along with a fresh HijackThis log, please :)
 
here is combofix report:
"User" - 07-04-11 19:41:19 Service Pack 2
ComboFix 07-03-27.4.2 - Running from: "C:\Documents and Settings\User\Desktop"


((((((((((((((((((((((((((((((( Files Created from 2007-03-11 to 2007-04-11 ))))))))))))))))))))))))))))))))))


2007-04-11 19:37 123,972 --a------ C:\WINDOWS\system32\nqaxhvoy.dll
2007-04-11 19:36 770,958 ---hs---- C:\WINDOWS\system32\vyccf.bak2
2007-04-11 19:35 91,887 --a------ C:\DOCUME~1\User\in.exe
2007-04-11 19:35 26,694 --a------ C:\WINDOWS\system32\pmnooll.dll
2007-04-10 20:31 26,694 --a------ C:\WINDOWS\system32\khfcaaa.dll
2007-04-10 19:30 770,686 ---hs---- C:\WINDOWS\system32\vyccf.ini2
2007-04-10 19:29 26,694 --a------ C:\WINDOWS\system32\cbxvuts.dll
2007-04-10 19:11 26,694 --a------ C:\WINDOWS\system32\wvuvuvw.dll
2007-04-10 19:04 771,313 ---hs---- C:\WINDOWS\system32\vyccf.bak1
2007-04-10 19:04 48,708 --a------ C:\WINDOWS\system32\mnervdak.dll
2007-04-10 19:04 280,676 ---hs---- C:\WINDOWS\system32\fccyv.dll
2007-04-10 18:43 772,347 ---hs---- C:\WINDOWS\system32\ehhjl.bak2
2007-04-10 18:42 26,694 --a------ C:\WINDOWS\system32\wvusssq.dll
2007-04-10 18:42 189,952 --a------ C:\DOCUME~1\User\us.exe
2007-04-01 17:10 602,112 --a------ C:\DOCUME~1\User\x.exe
2007-04-01 17:01 759,003 ---hs---- C:\WINDOWS\system32\ehhjl.bak1
2007-04-01 12:19 <DIR> d----c--- C:\avenger
2007-03-31 19:23 <DIR> d----c--- C:\!KillBox
2007-03-30 18:16 2,874 --a------ C:\WINDOWS\system32\tmp.reg
2007-03-30 18:15 79,360 --a------ C:\WINDOWS\system32\swxcacls.exe
2007-03-30 18:15 53,248 --a------ C:\WINDOWS\system32\Process.exe
2007-03-30 18:15 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2007-03-30 18:15 40,960 --a------ C:\WINDOWS\system32\swsc.exe
2007-03-30 18:15 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2007-03-30 18:15 135,168 --a------ C:\WINDOWS\system32\swreg.exe
2007-03-30 16:54 524,288 --ah----- C:\DOCUME~1\ADMINI~1\NTUSER.DAT
2007-03-26 20:04 <DIR> d-------- C:\VundoFix Backups
2007-03-22 17:19 <DIR> d-a------ C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2007-03-26 18:51 -------- d-------- C:\Program Files\windows live toolbar
2007-03-26 18:49 -------- d-------- C:\Program Files\yahoo!
2007-03-26 18:48 -------- d-------- C:\Program Files\msn messenger
2007-03-26 18:48 -------- d-------- C:\Program Files\motherboard monitor 5
2007-03-22 19:21 -------- d-------- C:\Program Files\norton internet security
2007-03-17 14:43 292864 --a------ C:\WINDOWS\system32\winsrv.dll
2007-03-08 16:36 577536 --a------ C:\WINDOWS\system32\user32.dll
2007-03-08 16:36 40960 --a------ C:\WINDOWS\system32\mf3216.dll
2007-03-08 16:36 281600 --a------ C:\WINDOWS\system32\gdi32.dll
2007-03-08 14:47 1843584 --a------ C:\WINDOWS\system32\win32k.sys
2007-03-03 16:33 -------- d-------- C:\Program Files\java
2007-02-05 21:17 185344 --a------ C:\WINDOWS\system32\upnphost.dll
2007-01-24 18:47 48776 --a------ C:\WINDOWS\system32\s32evnt1.dll
2007-01-19 13:53 51056 --a------ C:\WINDOWS\system32\sirenacm.dll


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries & legit default entries are not shown

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\ctfmon.exe"
"MsnMsgr"="\"C:\\Program Files\\MSN Messenger\\MsnMsgr.Exe\" /background"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"ATIPTA"="\"C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe\""
"igfxtray"="C:\\WINDOWS\\System32\\igfxtray.exe"
"igfxhkcmd"="C:\\WINDOWS\\System32\\hkcmd.exe"
"igfxpers"="C:\\WINDOWS\\System32\\igfxpers.exe"
"Dell Photo AIO Printer 922"="\"C:\\Program Files\\Dell Photo AIO Printer 922\\dlbtbmgr.exe\""
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_11\\bin\\jusched.exe\""
"ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
"osCheck"="\"C:\\Program Files\\Norton Internet Security\\osCheck.exe\""
"Symantec PIF AlertEng"="\"C:\\Program Files\\Common Files\\Symantec Shared\\PIF\\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\\PIFSvc.exe\" /a /m \"C:\\Program Files\\Common Files\\Symantec Shared\\PIF\\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\\AlertEng.dll\""

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"


[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{7D064D71-DD76-4596-90C0-921766AD560A}"=""
"{9796007A-181E-4C97-99EB-7F71B8989A7B}"=""

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cbxvuts
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\fccyv

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0

*newlycreated* - HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\LEGACY_COMHOST


Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\Norton Internet Security - Run Full System Scan - User.job


********************************************************************

catchme 0.2 W2K/XP/Vista - userland rootkit detector by Gmer, 17 October 2006
http://www.gmer.net

scanning hidden processes ...

scanning hidden services ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0

********************************************************************

Completion time: 07-04-11 19:57:34
C:\ComboFix2.txt ... 07-04-01 17:13
C:\ComboFix3.txt ... 07-04-01 12:33
 
here is hjt file:
Logfile of HijackThis v1.99.1
Scan saved at 20:13:51, on 11/04/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\igfxpers.exe
C:\WINDOWS\System32\igfxsrvc.exe
C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\cc"User" - 07-04-11 19:41:19 Service Pack 2
ComboFix 07-03-27.4.2 - Running from: "C:\Documents and Settings\User\Desktop"


((((((((((((((((((((((((((((((( Files Created from 2007-03-11 to 2007-04-11 ))))))))))))))))))))))))))))))))))


2007-04-11 19:37 123,972 --a------ C:\WINDOWS\system32\nqaxhvoy.dll
2007-04-11 19:36 770,958 ---hs---- C:\WINDOWS\system32\vyccf.bak2
2007-04-11 19:35 91,887 --a------ C:\DOCUME~1\User\in.exe
2007-04-11 19:35 26,694 --a------ C:\WINDOWS\system32\pmnooll.dll
2007-04-10 20:31 26,694 --a------ C:\WINDOWS\system32\khfcaaa.dll
2007-04-10 19:30 770,686 ---hs---- C:\WINDOWS\system32\vyccf.ini2
2007-04-10 19:29 26,694 --a------ C:\WINDOWS\system32\cbxvuts.dll
2007-04-10 19:11 26,694 --a------ C:\WINDOWS\system32\wvuvuvw.dll
2007-04-10 19:04 771,313 ---hs---- C:\WINDOWS\system32\vyccf.bak1
2007-04-10 19:04 48,708 --a------ C:\WINDOWS\system32\mnervdak.dll
2007-04-10 19:04 280,676 ---hs---- C:\WINDOWS\system32\fccyv.dll
2007-04-10 18:43 772,347 ---hs---- C:\WINDOWS\system32\ehhjl.bak2
2007-04-10 18:42 26,694 --a------ C:\WINDOWS\system32\wvusssq.dll
2007-04-10 18:42 189,952 --a------ C:\DOCUME~1\User\us.exe
2007-04-01 17:10 602,112 --a------ C:\DOCUME~1\User\x.exe
2007-04-01 17:01 759,003 ---hs---- C:\WINDOWS\system32\ehhjl.bak1
2007-04-01 12:19 <DIR> d----c--- C:\avenger
2007-03-31 19:23 <DIR> d----c--- C:\!KillBox
2007-03-30 18:16 2,874 --a------ C:\WINDOWS\system32\tmp.reg
2007-03-30 18:15 79,360 --a------ C:\WINDOWS\system32\swxcacls.exe
2007-03-30 18:15 53,248 --a------ C:\WINDOWS\system32\Process.exe
2007-03-30 18:15 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2007-03-30 18:15 40,960 --a------ C:\WINDOWS\system32\swsc.exe
2007-03-30 18:15 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2007-03-30 18:15 135,168 --a------ C:\WINDOWS\system32\swreg.exe
2007-03-30 16:54 524,288 --ah----- C:\DOCUME~1\ADMINI~1\NTUSER.DAT
2007-03-26 20:04 <DIR> d-------- C:\VundoFix Backups
2007-03-22 17:19 <DIR> d-a------ C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2007-03-26 18:51 -------- d-------- C:\Program Files\windows live toolbar
2007-03-26 18:49 -------- d-------- C:\Program Files\yahoo!
2007-03-26 18:48 -------- d-------- C:\Program Files\msn messenger
2007-03-26 18:48 -------- d-------- C:\Program Files\motherboard monitor 5
2007-03-22 19:21 -------- d-------- C:\Program Files\norton internet security
2007-03-17 14:43 292864 --a------ C:\WINDOWS\system32\winsrv.dll
2007-03-08 16:36 577536 --a------ C:\WINDOWS\system32\user32.dll
2007-03-08 16:36 40960 --a------ C:\WINDOWS\system32\mf3216.dll
2007-03-08 16:36 281600 --a------ C:\WINDOWS\system32\gdi32.dll
2007-03-08 14:47 1843584 --a------ C:\WINDOWS\system32\win32k.sys
2007-03-03 16:33 -------- d-------- C:\Program Files\java
2007-02-05 21:17 185344 --a------ C:\WINDOWS\system32\upnphost.dll
2007-01-24 18:47 48776 --a------ C:\WINDOWS\system32\s32evnt1.dll
2007-01-19 13:53 51056 --a------ C:\WINDOWS\system32\sirenacm.dll


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries & legit default entries are not shown

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\ctfmon.exe"
"MsnMsgr"="\"C:\\Program Files\\MSN Messenger\\MsnMsgr.Exe\" /background"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"ATIPTA"="\"C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe\""
"igfxtray"="C:\\WINDOWS\\System32\\igfxtray.exe"
"igfxhkcmd"="C:\\WINDOWS\\System32\\hkcmd.exe"
"igfxpers"="C:\\WINDOWS\\System32\\igfxpers.exe"
"Dell Photo AIO Printer 922"="\"C:\\Program Files\\Dell Photo AIO Printer 922\\dlbtbmgr.exe\""
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_11\\bin\\jusched.exe\""
"ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
"osCheck"="\"C:\\Program Files\\Norton Internet Security\\osCheck.exe\""
"Symantec PIF AlertEng"="\"C:\\Program Files\\Common Files\\Symantec Shared\\PIF\\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\\PIFSvc.exe\" /a /m \"C:\\Program Files\\Common Files\\Symantec Shared\\PIF\\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\\AlertEng.dll\""

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"


[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{7D064D71-DD76-4596-90C0-921766AD560A}"=""
"{9796007A-181E-4C97-99EB-7F71B8989A7B}"=""

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cbxvuts
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\fccyv

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0

*newlycreated* - HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\LEGACY_COMHOST


Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\Norton Internet Security - Run Full System Scan - User.job


********************************************************************

catchme 0.2 W2K/XP/Vista - userland rootkit detector by Gmer, 17 October 2006
http://www.gmer.net

scanning hidden processes ...

scanning hidden services ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0

********************************************************************

Completion time: 07-04-11 19:57:34
C:\ComboFix2.txt ... 07-04-01 17:13
C:\ComboFix3.txt ... 07-04-01 12:33
App.exe
C:\Program Files\Dell Photo AIO Printer 922\dlbtbmon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Documents and Settings\User\Desktop\HJT.exe

O2 - BHO: (no name) - {08D3A5C1-B6A5-47DD-875A-03B47E1F030E} - C:\WINDOWS\system32\fccyv.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
O2 - BHO: (no name) - {2487839D-CBCF-4CCF-9826-6390CFACAFAE} - C:\WINDOWS\system32\ljhhe.dll (file missing)
O2 - BHO: (no name) - {67C55A8D-E808-4caa-9EA7-F77102DE0BB6} - C:\WINDOWS\system32\mnervdak.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: (no name) - {7D064D71-DD76-4596-90C0-921766AD560A} - C:\WINDOWS\system32\pmnnmlj.dll (file missing)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {9796007A-181E-4C97-99EB-7F71B8989A7B} - C:\WINDOWS\system32\cbxvuts.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\System32\igfxpers.exe
O4 - HKLM\..\Run: [Dell Photo AIO Printer 922] "C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-GB/a-UNO1/GAME_UNO1.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: cbxvuts - C:\WINDOWS\SYSTEM32\cbxvuts.dll
O20 - Winlogon Notify: fccyv - C:\WINDOWS\system32\fccyv.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: dlbt_device - Dell - C:\WINDOWS\system32\dlbtcoms.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing)
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
 
Hi

This might be a bit difficult process but ask if any questions (this have worked in one similar case).

1) Make your hidden and system files visible -> http://www.xtra.co.nz/help/0,,4155-1916458,00.html

Boot in safe mode (not in safe mode with networking!)

2) Empty this folder -> C:\Windows\Prefetch & empty Recycle Bin

3) Use process explorer and otmoveit to files in 020 lines (not to this -> O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll)

4) Use otmoveit to these files:

C:\WINDOWS\system32\nqaxhvoy.dll
C:\WINDOWS\system32\vyccf.bak2
C:\DOCUME~1\User\in.exe
C:\WINDOWS\system32\pmnooll.dll
C:\WINDOWS\system32\khfcaaa.dll
C:\WINDOWS\system32\vyccf.ini2
C:\WINDOWS\system32\cbxvuts.dll
C:\WINDOWS\system32\wvuvuvw.dll
C:\WINDOWS\system32\vyccf.bak1
C:\WINDOWS\system32\mnervdak.dll
C:\WINDOWS\system32\fccyv.dll
C:\WINDOWS\system32\ehhjl.bak2
C:\WINDOWS\system32\wvusssq.dll
C:\DOCUME~1\User\us.exe
C:\DOCUME~1\User\x.exe
C:\WINDOWS\system32\ehhjl.bak1

5) Use otmoveit also to any suspicious looking dll in system32 directory that has been created today or yesterday

6) Fix all 02 & 020 lines with file missing

Reboot

Re-run combofix

Re-run vundofix

Post:

- a fresh HijackThis log
- combofix log
- vundofix report
 
here is combofix:
"User" - 07-04-12 11:25:12 Service Pack 2
ComboFix 07-03-27.4.2 - Running from: "C:\Documents and Settings\User\Desktop"


((((((((((((((((((((((((((((((( Files Created from 2007-03-12 to 2007-04-12 ))))))))))))))))))))))))))))))))))


2007-04-12 11:25 26,694 --a------ C:\WINDOWS\system32\ddccyyx.dll
2007-04-12 11:25 189,952 --a------ C:\DOCUME~1\User\us.exe
2007-04-12 10:53 26,694 --a------ C:\WINDOWS\system32\gebawxx.dll
2007-04-12 10:53 123,972 --a------ C:\WINDOWS\system32\sdhntdti.dll
2007-04-01 12:19 <DIR> d----c--- C:\avenger
2007-03-31 19:23 <DIR> d----c--- C:\!KillBox
2007-03-30 18:16 2,874 --a------ C:\WINDOWS\system32\tmp.reg
2007-03-30 18:15 79,360 --a------ C:\WINDOWS\system32\swxcacls.exe
2007-03-30 18:15 53,248 --a------ C:\WINDOWS\system32\Process.exe
2007-03-30 18:15 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2007-03-30 18:15 40,960 --a------ C:\WINDOWS\system32\swsc.exe
2007-03-30 18:15 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2007-03-30 18:15 135,168 --a------ C:\WINDOWS\system32\swreg.exe
2007-03-30 16:54 524,288 --ah----- C:\DOCUME~1\ADMINI~1\NTUSER.DAT
2007-03-26 20:04 <DIR> d-------- C:\VundoFix Backups
2007-03-22 17:19 <DIR> d-a------ C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2007-04-12 11:31 280676 ---hs---- C:\WINDOWS\system32\jkhig.dll
2007-03-26 18:51 -------- d-------- C:\Program Files\windows live toolbar
2007-03-26 18:49 -------- d-------- C:\Program Files\yahoo!
2007-03-26 18:48 -------- d-------- C:\Program Files\msn messenger
2007-03-26 18:48 -------- d-------- C:\Program Files\motherboard monitor 5
2007-03-22 19:21 -------- d-------- C:\Program Files\norton internet security
2007-03-17 14:43 292864 --a------ C:\WINDOWS\system32\winsrv.dll
2007-03-08 16:36 577536 --a------ C:\WINDOWS\system32\user32.dll
2007-03-08 16:36 40960 --a------ C:\WINDOWS\system32\mf3216.dll
2007-03-08 16:36 281600 --a------ C:\WINDOWS\system32\gdi32.dll
2007-03-08 14:47 1843584 --a------ C:\WINDOWS\system32\win32k.sys
2007-03-03 16:33 -------- d-------- C:\Program Files\java
2007-02-05 21:17 185344 --a------ C:\WINDOWS\system32\upnphost.dll
2007-01-24 18:47 48776 --a------ C:\WINDOWS\system32\s32evnt1.dll
2007-01-19 13:53 51056 --a------ C:\WINDOWS\system32\sirenacm.dll


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries & legit default entries are not shown

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\ctfmon.exe"
"MsnMsgr"="\"C:\\Program Files\\MSN Messenger\\MsnMsgr.Exe\" /background"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"ATIPTA"="\"C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe\""
"igfxtray"="C:\\WINDOWS\\System32\\igfxtray.exe"
"igfxhkcmd"="C:\\WINDOWS\\System32\\hkcmd.exe"
"igfxpers"="C:\\WINDOWS\\System32\\igfxpers.exe"
"Dell Photo AIO Printer 922"="\"C:\\Program Files\\Dell Photo AIO Printer 922\\dlbtbmgr.exe\""
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_11\\bin\\jusched.exe\""
"ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
"osCheck"="\"C:\\Program Files\\Norton Internet Security\\osCheck.exe\""
"Symantec PIF AlertEng"="\"C:\\Program Files\\Common Files\\Symantec Shared\\PIF\\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\\PIFSvc.exe\" /a /m \"C:\\Program Files\\Common Files\\Symantec Shared\\PIF\\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\\AlertEng.dll\""

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"


[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{7D064D71-DD76-4596-90C0-921766AD560A}"=""
"{9796007A-181E-4C97-99EB-7F71B8989A7B}"=""

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ddccyyx
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\jkhig

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0

*newlycreated* - HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\LEGACY_COMHOST


Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\Norton Internet Security - Run Full System Scan - User.job


********************************************************************

catchme 0.2 W2K/XP/Vista - userland rootkit detector by Gmer, 17 October 2006
http://www.gmer.net

scanning hidden processes ...

scanning hidden services ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0

********************************************************************

Completion time: 07-04-12 11:34:18
C:\ComboFix2.txt ... 07-04-11 19:57
C:\ComboFix3.txt ... 07-04-01 17:13
 
forget my last combofix report, this is the new 1, the other logs will be on the way in a few minutes:

"User" - 07-04-13 9:48:12 Service Pack 2
ComboFix 07-03-27.4.2 - Running from: "C:\Documents and Settings\User\Desktop"


((((((((((((((((((((((((((((((( Files Created from 2007-03-13 to 2007-04-13 ))))))))))))))))))))))))))))))))))


2007-04-13 09:54 766,247 ---hs---- C:\WINDOWS\system32\orqru.bak1
2007-04-13 09:54 123,972 --a------ C:\WINDOWS\system32\wdrrxwal.dll
2007-04-13 09:53 280,676 ---hs---- C:\WINDOWS\system32\urqro.dll
2007-04-12 16:37 768,354 ---hs---- C:\WINDOWS\system32\mmllm.bak1
2007-04-12 11:25 26,694 --a------ C:\WINDOWS\system32\ddccyyx.dll
2007-04-12 10:53 26,694 --a------ C:\WINDOWS\system32\gebawxx.dll
2007-04-01 12:19 <DIR> d----c--- C:\avenger
2007-03-31 19:23 <DIR> d----c--- C:\!KillBox
2007-03-30 18:16 2,874 --a------ C:\WINDOWS\system32\tmp.reg
2007-03-30 18:15 79,360 --a------ C:\WINDOWS\system32\swxcacls.exe
2007-03-30 18:15 53,248 --a------ C:\WINDOWS\system32\Process.exe
2007-03-30 18:15 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2007-03-30 18:15 40,960 --a------ C:\WINDOWS\system32\swsc.exe
2007-03-30 18:15 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2007-03-30 18:15 135,168 --a------ C:\WINDOWS\system32\swreg.exe
2007-03-30 16:54 524,288 --ah----- C:\DOCUME~1\ADMINI~1\NTUSER.DAT
2007-03-26 20:04 <DIR> d-------- C:\VundoFix Backups
2007-03-22 17:19 <DIR> d-a------ C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2007-03-26 18:51 -------- d-------- C:\Program Files\windows live toolbar
2007-03-26 18:49 -------- d-------- C:\Program Files\yahoo!
2007-03-26 18:48 -------- d-------- C:\Program Files\msn messenger
2007-03-26 18:48 -------- d-------- C:\Program Files\motherboard monitor 5
2007-03-22 19:21 -------- d-------- C:\Program Files\norton internet security
2007-03-17 14:43 292864 --a------ C:\WINDOWS\system32\winsrv.dll
2007-03-08 16:36 577536 --a------ C:\WINDOWS\system32\user32.dll
2007-03-08 16:36 40960 --a------ C:\WINDOWS\system32\mf3216.dll
2007-03-08 16:36 281600 --a------ C:\WINDOWS\system32\gdi32.dll
2007-03-08 14:47 1843584 --a------ C:\WINDOWS\system32\win32k.sys
2007-03-03 16:33 -------- d-------- C:\Program Files\java
2007-02-05 21:17 185344 --a------ C:\WINDOWS\system32\upnphost.dll
2007-01-24 18:47 48776 --a------ C:\WINDOWS\system32\s32evnt1.dll
2007-01-19 13:53 51056 --a------ C:\WINDOWS\system32\sirenacm.dll


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries & legit default entries are not shown

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\ctfmon.exe"
"MsnMsgr"="\"C:\\Program Files\\MSN Messenger\\MsnMsgr.Exe\" /background"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"ATIPTA"="\"C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe\""
"igfxtray"="C:\\WINDOWS\\System32\\igfxtray.exe"
"igfxhkcmd"="C:\\WINDOWS\\System32\\hkcmd.exe"
"igfxpers"="C:\\WINDOWS\\System32\\igfxpers.exe"
"Dell Photo AIO Printer 922"="\"C:\\Program Files\\Dell Photo AIO Printer 922\\dlbtbmgr.exe\""
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_11\\bin\\jusched.exe\""
"ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
"osCheck"="\"C:\\Program Files\\Norton Internet Security\\osCheck.exe\""
"Symantec PIF AlertEng"="\"C:\\Program Files\\Common Files\\Symantec Shared\\PIF\\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\\PIFSvc.exe\" /a /m \"C:\\Program Files\\Common Files\\Symantec Shared\\PIF\\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\\AlertEng.dll\""

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"


[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{7D064D71-DD76-4596-90C0-921766AD560A}"=""
"{9796007A-181E-4C97-99EB-7F71B8989A7B}"=""

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ddccyyx
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\urqro

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0

*newlycreated* - HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\LEGACY_COMHOST


Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\Norton Internet Security - Run Full System Scan - User.job


********************************************************************

catchme 0.2 W2K/XP/Vista - userland rootkit detector by Gmer, 17 October 2006
http://www.gmer.net

scanning hidden processes ...

scanning hidden services ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0

********************************************************************

Completion time: 07-04-13 10:02:28
C:\ComboFix2.txt ... 07-04-12 11:34
C:\ComboFix3.txt ... 07-04-11 19:57
 
here is hjt logfile, but i can see that vundo has mutated again:

Logfile of HijackThis v1.99.1
Scan saved at 10:23:14, on 13/04/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\igfxsrvc.exe
C:\WINDOWS\System32\igfxpers.exe
C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\Program Files\Dell Photo AIO Printer 922\dlbtbmon.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\User\Desktop\HJT.exe

O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {9796007A-181E-4C97-99EB-7F71B8989A7B} - C:\WINDOWS\system32\ddccyyx.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\System32\igfxpers.exe
O4 - HKLM\..\Run: [Dell Photo AIO Printer 922] "C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-GB/a-UNO1/GAME_UNO1.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: ddccyyx - C:\WINDOWS\SYSTEM32\ddccyyx.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: dlbt_device - Dell - C:\WINDOWS\system32\dlbtcoms.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing)
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
 
here is vundofix logfile:


VundoFix V6.3.17

Checking Java version...

Java version is 1.5.0.9
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.10

Java version is 1.5.0.11

Scan started at 20:04:44 26/03/2007

Listing files found while scanning....


Beginning removal...

VundoFix V6.3.17

Checking Java version...

Java version is 1.5.0.9
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.10

Java version is 1.5.0.11

Scan started at 20:09:40 26/03/2007

Listing files found while scanning....


VundoFix V6.3.17

Checking Java version...

Java version is 1.5.0.9
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.10

Java version is 1.5.0.11

Scan started at 20:18:00 26/03/2007

Listing files found while scanning....


Beginning removal...

VundoFix V6.3.17

Checking Java version...

Java version is 1.5.0.9
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.10

Java version is 1.5.0.11

Scan started at 20:18:43 26/03/2007

Listing files found while scanning....

C:\WINDOWS\system32\ilkkj.bak1
C:\WINDOWS\system32\ilkkj.ini
C:\WINDOWS\system32\jkkli.dll
C:\WINDOWS\system32\xneufrpi.dll

Beginning removal...

Attempting to delete C:\WINDOWS\system32\ilkkj.bak1
C:\WINDOWS\system32\ilkkj.bak1 Has been deleted!

Attempting to delete C:\WINDOWS\system32\ilkkj.ini
C:\WINDOWS\system32\ilkkj.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\jkkli.dll
C:\WINDOWS\system32\jkkli.dll Could not be deleted.

Attempting to delete C:\WINDOWS\system32\xneufrpi.dll
C:\WINDOWS\system32\xneufrpi.dll Has been deleted!

Performing Repairs to the registry.
Done!

Beginning removal...

Attempting to delete C:\WINDOWS\system32\jkkli.dll
C:\WINDOWS\system32\jkkli.dll Has been deleted!

Performing Repairs to the registry.
Done!

VundoFix V6.3.17

Checking Java version...

Java version is 1.5.0.9
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.10

Java version is 1.5.0.11

Scan started at 20:58:57 26/03/2007

Listing files found while scanning....

C:\WINDOWS\system32\ilnpo.bak1
C:\WINDOWS\system32\ilnpo.ini
C:\WINDOWS\system32\opnli.dll

Beginning removal...

Attempting to delete C:\WINDOWS\system32\ilnpo.bak1
C:\WINDOWS\system32\ilnpo.bak1 Has been deleted!

Attempting to delete C:\WINDOWS\system32\ilnpo.ini
C:\WINDOWS\system32\ilnpo.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\opnli.dll
C:\WINDOWS\system32\opnli.dll Could not be deleted.

Performing Repairs to the registry.
Done!

Beginning removal...

Attempting to delete C:\WINDOWS\system32\opnli.dll
C:\WINDOWS\system32\opnli.dll Has been deleted!

Performing Repairs to the registry.
Done!

VundoFix V6.3.18

Checking Java version...

Java version is 1.5.0.9
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.10

Java version is 1.5.0.11

Scan started at 16:23:51 31/03/2007

Listing files found while scanning....

C:\WINDOWS\system32\awtqnkh.dll
C:\WINDOWS\system32\awtuvvv.dll
C:\WINDOWS\system32\byxwutq.dll
C:\WINDOWS\system32\byxxyya.dll
C:\WINDOWS\system32\byxywxx.dll
C:\WINDOWS\system32\cbxxwxv.dll
C:\WINDOWS\system32\fccabyx.dll
C:\WINDOWS\system32\fccbbax.dll
C:\WINDOWS\system32\fccccda.dll
C:\WINDOWS\system32\gebay.dll
C:\WINDOWS\system32\gebbbbx.dll
C:\WINDOWS\system32\gebbyvv.dll
C:\WINDOWS\system32\gebxw.dll
C:\WINDOWS\system32\hgghghh.dll
C:\WINDOWS\system32\iifcyaa.dll
C:\WINDOWS\system32\iifdaab.dll
C:\WINDOWS\system32\jkhgh.dll
C:\WINDOWS\system32\jkkkjgh.dll
C:\WINDOWS\system32\ljjhihg.dll
C:\WINDOWS\system32\nnnkigh.dll
C:\WINDOWS\system32\nnnlihf.dll
C:\WINDOWS\system32\nnnopnk.dll
C:\WINDOWS\system32\opnoonk.dll
C:\WINDOWS\system32\pmnkhif.dll
C:\WINDOWS\system32\pmnlife.dll
C:\WINDOWS\system32\pmnnnnm.dll
C:\WINDOWS\system32\qomnnnm.dll
C:\WINDOWS\system32\rqrqqpo.dll
C:\WINDOWS\system32\rqrrpol.dll
C:\WINDOWS\system32\ssqomjk.dll
C:\WINDOWS\system32\ssqon.dll
C:\WINDOWS\system32\ssqqppm.dll
C:\WINDOWS\system32\ssqrsss.dll
C:\WINDOWS\system32\tusrq.dll
C:\WINDOWS\system32\vtutqom.dll
C:\WINDOWS\system32\vtuursq.dll
C:\WINDOWS\system32\wvurstu.dll
C:\WINDOWS\system32\wvussqr.dll
C:\WINDOWS\system32\wvwxw.dll
C:\WINDOWS\system32\wxbeg.ini
C:\WINDOWS\system32\wxwvw.bak1
C:\WINDOWS\system32\wxwvw.bak2
C:\WINDOWS\system32\wxwvw.ini
C:\WINDOWS\system32\wxwvw.ini2
C:\WINDOWS\system32\wxwvw.tmp
C:\WINDOWS\system32\xxyabbb.dll
C:\WINDOWS\system32\xxyawvv.dll

Beginning removal...

Attempting to delete C:\WINDOWS\system32\awtqnkh.dll
C:\WINDOWS\system32\awtqnkh.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\awtuvvv.dll
C:\WINDOWS\system32\awtuvvv.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\byxwutq.dll
C:\WINDOWS\system32\byxwutq.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\byxxyya.dll
C:\WINDOWS\system32\byxxyya.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\byxywxx.dll
C:\WINDOWS\system32\byxywxx.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\cbxxwxv.dll
C:\WINDOWS\system32\cbxxwxv.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\fccabyx.dll
C:\WINDOWS\system32\fccabyx.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\fccbbax.dll
C:\WINDOWS\system32\fccbbax.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\fccccda.dll
C:\WINDOWS\system32\fccccda.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\gebay.dll
C:\WINDOWS\system32\gebay.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\gebbbbx.dll
C:\WINDOWS\system32\gebbbbx.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\gebbyvv.dll
C:\WINDOWS\system32\gebbyvv.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\gebxw.dll
C:\WINDOWS\system32\gebxw.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\hgghghh.dll
C:\WINDOWS\system32\hgghghh.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\iifcyaa.dll
C:\WINDOWS\system32\iifcyaa.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\iifdaab.dll
C:\WINDOWS\system32\iifdaab.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\jkhgh.dll
C:\WINDOWS\system32\jkhgh.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\jkkkjgh.dll
C:\WINDOWS\system32\jkkkjgh.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ljjhihg.dll
C:\WINDOWS\system32\ljjhihg.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\nnnkigh.dll
C:\WINDOWS\system32\nnnkigh.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\nnnlihf.dll
C:\WINDOWS\system32\nnnlihf.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\nnnopnk.dll
C:\WINDOWS\system32\nnnopnk.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\opnoonk.dll
C:\WINDOWS\system32\opnoonk.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\pmnkhif.dll
C:\WINDOWS\system32\pmnkhif.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\pmnlife.dll
C:\WINDOWS\system32\pmnlife.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\pmnnnnm.dll
C:\WINDOWS\system32\pmnnnnm.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\qomnnnm.dll
C:\WINDOWS\system32\qomnnnm.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\rqrqqpo.dll
C:\WINDOWS\system32\rqrqqpo.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\rqrrpol.dll
C:\WINDOWS\system32\rqrrpol.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ssqomjk.dll
C:\WINDOWS\system32\ssqomjk.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ssqon.dll
C:\WINDOWS\system32\ssqon.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ssqqppm.dll
C:\WINDOWS\system32\ssqqppm.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ssqrsss.dll
C:\WINDOWS\system32\ssqrsss.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\tusrq.dll
C:\WINDOWS\system32\tusrq.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\vtutqom.dll
C:\WINDOWS\system32\vtutqom.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\vtuursq.dll
C:\WINDOWS\system32\vtuursq.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\wvurstu.dll
C:\WINDOWS\system32\wvurstu.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\wvussqr.dll
C:\WINDOWS\system32\wvussqr.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\wvwxw.dll
C:\WINDOWS\system32\wvwxw.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\wxbeg.ini
C:\WINDOWS\system32\wxbeg.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\wxwvw.bak1
C:\WINDOWS\system32\wxwvw.bak1 Has been deleted!

Attempting to delete C:\WINDOWS\system32\wxwvw.bak2
C:\WINDOWS\system32\wxwvw.bak2 Has been deleted!

Attempting to delete C:\WINDOWS\system32\wxwvw.ini
C:\WINDOWS\system32\wxwvw.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\wxwvw.ini2
C:\WINDOWS\system32\wxwvw.ini2 Has been deleted!

Attempting to delete C:\WINDOWS\system32\wxwvw.tmp
C:\WINDOWS\system32\wxwvw.tmp Has been deleted!

Attempting to delete C:\WINDOWS\system32\xxyabbb.dll
C:\WINDOWS\system32\xxyabbb.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\xxyawvv.dll
C:\WINDOWS\system32\xxyawvv.dll Has been deleted!

Performing Repairs to the registry.
Done!

VundoFix V6.3.18

Checking Java version...

Java version is 1.5.0.9
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.10

Java version is 1.5.0.11

Scan started at 17:30:50 31/03/2007

Listing files found while scanning....

C:\WINDOWS\system32\cdccf.ini2
C:\WINDOWS\system32\cdccf.tmp
C:\WINDOWS\system32\fccdc.dll
C:\WINDOWS\system32\pmnkhif.dll

Beginning removal...

Attempting to delete C:\WINDOWS\system32\cdccf.ini2
C:\WINDOWS\system32\cdccf.ini2 Has been deleted!

Attempting to delete C:\WINDOWS\system32\cdccf.tmp
C:\WINDOWS\system32\cdccf.tmp Has been deleted!

Attempting to delete C:\WINDOWS\system32\fccdc.dll
C:\WINDOWS\system32\fccdc.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\pmnkhif.dll
C:\WINDOWS\system32\pmnkhif.dll Has been deleted!

Performing Repairs to the registry.
Done!

VundoFix V6.3.18

Checking Java version...

Java version is 1.5.0.9
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.10

Java version is 1.5.0.11

Scan started at 17:52:47 31/03/2007

Listing files found while scanning....

C:\WINDOWS\system32\cbxxutt.dll
C:\WINDOWS\system32\loppo.bak1
C:\WINDOWS\system32\loppo.ini
C:\WINDOWS\system32\oppol.dll

Beginning removal...

Attempting to delete C:\WINDOWS\system32\cbxxutt.dll
C:\WINDOWS\system32\cbxxutt.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\loppo.bak1
C:\WINDOWS\system32\loppo.bak1 Has been deleted!

Attempting to delete C:\WINDOWS\system32\loppo.ini
C:\WINDOWS\system32\loppo.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\oppol.dll
C:\WINDOWS\system32\oppol.dll Has been deleted!

Performing Repairs to the registry.
Done!

Beginning removal...

Performing Repairs to the registry.
Done!

VundoFix V6.3.18

Checking Java version...

Java version is 1.5.0.9
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.10

Java version is 1.5.0.11

Scan started at 11:38:15 12/04/2007

Listing files found while scanning....

C:\WINDOWS\system32\gihkj.bak1
C:\WINDOWS\system32\gihkj.ini
C:\WINDOWS\system32\hfssedic.dll
C:\WINDOWS\system32\jkhig.dll
C:\WINDOWS\system32\nwpusfew.dll
C:\WINDOWS\system32\sdhntdti.dll

Beginning removal...

Attempting to delete C:\WINDOWS\system32\gihkj.bak1
C:\WINDOWS\system32\gihkj.bak1 Has been deleted!

Attempting to delete C:\WINDOWS\system32\gihkj.ini
C:\WINDOWS\system32\gihkj.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\hfssedic.dll
C:\WINDOWS\system32\hfssedic.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\jkhig.dll
C:\WINDOWS\system32\jkhig.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\nwpusfew.dll
C:\WINDOWS\system32\nwpusfew.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\sdhntdti.dll
C:\WINDOWS\system32\sdhntdti.dll Has been deleted!

Performing Repairs to the registry.
Done!

VundoFix V6.3.18

Checking Java version...

Java version is 1.5.0.9
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.10

Java version is 1.5.0.11

Scan started at 16:42:14 12/04/2007

Listing files found while scanning....

C:\WINDOWS\system32\gagjmhsa.dll
C:\WINDOWS\system32\mllmm.dll
C:\WINDOWS\system32\mmllm.bak1
C:\WINDOWS\system32\mmllm.ini

Beginning removal...

Attempting to delete C:\WINDOWS\system32\gagjmhsa.dll
C:\WINDOWS\system32\gagjmhsa.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\mllmm.dll
C:\WINDOWS\system32\mllmm.dll Has been deleted!

Performing Repairs to the registry.
Done!

VundoFix V6.3.18

Checking Java version...

Java version is 1.5.0.9
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.10

Java version is 1.5.0.11

Scan started at 10:05:27 13/04/2007

Listing files found while scanning....

C:\WINDOWS\system32\orqru.bak1
C:\WINDOWS\system32\orqru.ini2
C:\WINDOWS\system32\orqru.tmp
C:\WINDOWS\system32\urqro.dll
C:\WINDOWS\system32\wdrrxwal.dll

Beginning removal...

Attempting to delete C:\WINDOWS\system32\orqru.bak1
C:\WINDOWS\system32\orqru.bak1 Has been deleted!

Attempting to delete C:\WINDOWS\system32\orqru.ini2
C:\WINDOWS\system32\orqru.ini2 Has been deleted!

Attempting to delete C:\WINDOWS\system32\orqru.tmp
C:\WINDOWS\system32\orqru.tmp Has been deleted!

Attempting to delete C:\WINDOWS\system32\urqro.dll
C:\WINDOWS\system32\urqro.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\wdrrxwal.dll
C:\WINDOWS\system32\wdrrxwal.dll Has been deleted!

Performing Repairs to the registry.
Done!
 
Hi

I'm afraid that you will have to do that process again like before :(

Make sure that hidden files are visible and you use otmoveit to all new dll files in system32 folder and also to these:

C:\WINDOWS\system32\orqru.bak1
C:\WINDOWS\system32\wdrrxwal.dll
C:\WINDOWS\system32\urqro.dll
C:\WINDOWS\system32\mmllm.bak1
C:\WINDOWS\system32\ddccyyx.dll
C:\WINDOWS\system32\gebawxx.dll

Re-run combofix

Re-run vundofix

Post:

- a fresh HijackThis log
- combofix log
- vundofix report
 
looks all clear on hjt:
Logfile of HijackThis v1.99.1
Scan saved at 16:21:21, on 13/04/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\igfxpers.exe
C:\WINDOWS\System32\igfxsrvc.exe
C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\Program Files\Dell Photo AIO Printer 922\dlbtbmon.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\User\Desktop\HJT.exe
C:\WINDOWS\system32\wuauclt.exe

O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\System32\igfxpers.exe
O4 - HKLM\..\Run: [Dell Photo AIO Printer 922] "C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-GB/a-UNO1/GAME_UNO1.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: dlbt_device - Dell - C:\WINDOWS\system32\dlbtcoms.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing)
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
 
Back
Top